The EU AI Act in Czech Republic
How Regulation (EU) 2024/1689 applies in Czech Republic, and the 5 AI instruments Czech Republic has of its own.
The EU AI Act
The EU AI Act establishes a comprehensive, risk-based legal framework to ensure safe, trustworthy, and human-centric AI systems across the European Union, protecting fundamental rights.
Key dates
- 1 Aug 2024— Entry into Force of the AI Act
- 2 Feb 2025— Prohibited AI practices and AI literacy obligations apply
- 2 Aug 2025— Governance rules and obligations for General-Purpose AI (GPAI) models apply
- 27 Jul 2026— Amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- 2 Dec 2026— Watermarking obligations on AI-generated content apply
- 2 Aug 2027— Obligations for high-risk AI systems included in Annex I of the AI Act apply
Czech Republic’s own AI instruments
5 records tracked for Czech Republic, beyond the EU-level Act above.
Czech Republic - AI Implementation Act
Czech Republic · 2025 · 1 Jan 2026
Czech Republic - AI Policy Coordination
Czech Republic · 2025 · 28 May 2025
Czech Republic - AI Strategy Action Plan (2025)
Czech Republic · 2025 · 2 Apr 2025
Czech Republic - Cybersecurity Act (264/2025)
Czech Republic · 2025 · 1 Nov 2025
Czech Republic - National AI Strategy (2019)
Czech Republic · 2019 · 6 May 2019
National authority in Czech Republic
Named in Czech Republic’s own records, not inferred.
Per Czech Republic - AI Implementation Act
- Ministry of Industry and Trade (MPO) — National coordinator and drafter of the adaptation act; policy lead and proposer of the bill
- Czech Telecommunication Office (ČTÚ) — Central market surveillance authority and public contact point for AI market issues
- Office for Technical Standardization, Metrology and State Testing (ÚNMZ) — Notifying authority (oznamující orgán) responsible for accreditation/notification of conformity assessment bodies
- Office for Personal Data Protection (ÚOOÚ) — Market surveillance and enforcement for AI systems implicating personal data and privacy
- Czech National Bank (ČNB) — Sectoral market surveillance and oversight for financial-sector AI uses under its supervisory remit
- Czech Agency for Standardization (ČAS / Agentura ČAS) — Operator and manager of the national regulatory sandbox and standardisation support
- Public Defender of Rights (Veřejný ochránce práv) — Human-rights oversight, review and stakeholder protection role in enforcement and sandbox governance
Per Czech Republic - AI Policy Coordination
- Ministry of Industry and Trade (MPO) — Host and national coordinator (gestor) for AI policy and implementation; convenes the Committee for Artificial Intelligence.
- Czech Telecommunication Office (ČTÚ) — Designated market surveillance / supervisory authority in areas assigned by MPO (e.g., market surveillance role for AI Act implementation as proposed).
- Office for Personal Data Protection (ÚOOÚ) — Data protection supervisor; responsible for GDPR‑related oversight and aspects of AI systems that implicate personal data and privacy rights.
- Czech National Bank (ČNB) — Sectoral supervisory authority with responsibilities for AI use in financial services where applicable.
- Office for Technical Standardisation, Metrology and State Testing (ÚNMZ) — Notifying authority / technical assessment coordination for conformity assessment and testing where applicable.
Per Czech Republic - AI Strategy Action Plan (2025)
- Ministry of Industry and Trade of the Czech Republic (MPO) — NAIS gestor and central coordinator of the Action Plan; publisher of NAIS documents and Implementační plán entries
- Government of the Czech Republic — Approving authority for Implementační plán programu Digitální Česko and annual Action Plans
- Office for Personal Data Protection (Úřad pro ochranu osobních údajů) — National supervisory authority for data protection and GDPR enforcement; consultative and enforcement role where personal data processing is involved
Per Czech Republic - Cybersecurity Act (264/2025)
- National Cyber and Information Security Office (NÚKIB) — Primary supervisory authority: registration, oversight, incident triage, enforcement and guidance.
- National CERT (GovCERT/Národní CERT) — Operational incident reception, technical coordination, technical support for incident handling and vulnerability management.
- Sectoral Regulators (examples) — Parallel supervision in sectoral domains (e.g., Czech National Bank, Energy Regulatory Office, Ministry of Health) with responsibilities for sector‑specific rules and coordination with NÚKIB.
Per Czech Republic - National AI Strategy (2019)
- Ministry of Industry and Trade (MPO) — Main coordinator of NAIS, implementation lead and publisher of the Strategy
- Government Office of the Czech Republic (Vláda ČR) — Government approval and high-level political oversight
- Office for Personal Data Protection (Úřad pro ochranu osobních údajů) — National data protection authority (GDPR enforcement and privacy oversight)
- National Cyber and Information Security Agency (NÚKIB) — Cybersecurity guidance and protection of critical information infrastructure
- Ministry of Defence / Ministry of Interior — Coordinators for defence, security and public safety-related AI applications (advisory roles in relevant chapters)
Penalties in Czech Republic
As stated in Czech Republic’s own records.
Per Czech Republic - AI Implementation Act
- Warnings and remedial orders for minor or first-time infractions, including timelines for corrective action.
- Administrative fines scaled to seriousness and turnover (aligned with the AI Act framework for maximum fines, with national discretion on lower levels and thresholds).
- Suspension or temporary prohibition of placing on the market or putting into service of non-compliant AI systems.
- Publication of enforcement decisions in cases of serious or systemic non-compliance.
- Revocation or suspension of accreditation for notified conformity assessment bodies in cases of malpractice.
- Possible administrative sanctions tailored for SMEs (reduced fines, admonitions) as signalled by MPO communications.
Per Czech Republic - AI Policy Coordination
- The committee itself does not levy penalties; it is advisory and coordinating in nature.
- Enforcement and sanctions for AI regulatory breaches rest with designated national competent authorities (e.g., ČTÚ, ÚNMZ, ÚOOÚ, ČNB) once national implementing measures are adopted.
- Potential penalties for AI Act breaches follow EU penalty frameworks which Member States must implement; at EU level these include high administrative fines for serious infringements (see EU legislative texts for details).
- The committee may recommend corrective measures, supervisory action and escalation to enforcement authorities but does not impose sanctions directly.
- Where national law or implementing rules create administrative offences, sanctions and appeal rights will be set out in those instruments and applied by competent authorities.
Per Czech Republic - AI Strategy Action Plan (2025)
- Withholding, suspension or termination of agreed funding tranches for non-compliant projects
- De-commitment or reallocation of funds where deliverables or compliance obligations are not met
- Administrative enforcement by sectoral regulators (e.g., fines, corrective orders for GDPR breaches by the Data Protection Authority)
- Contractual remedies under public procurement rules (termination, damages, blacklisting) for procurement non-compliance
- Referral to criminal or administrative enforcement bodies where statutory violations occur
Per Czech Republic - Cybersecurity Act (264/2025)
- Administrative fines for breaches, with statutory ranges including fines up to CZK 50,000,000 for the most serious offences (see the Act’s penalty provisions for categorical ceilings).
- Fines up to CZK 20,000,000 or lower ceilings for other categories of offences as specified in the Act, and fines for procedural failures up to CZK 2,000,000 in certain cases.
- Coercive fines and enforcement measures (donucovací pokuty) up to CZK 10,000,000 or amounts tied to turnover in specific enforcement scenarios.
- Orders to implement remedial or re‑active measures, temporary suspension of specified operations or supplier restrictions issued by NÚKIB.
- Personal liability exposure for statutory bodies where management repeatedly or grossly fails to meet obligations; potential suspension of functions of statutory bodies in extreme cases.
- Publication of enforcement decisions and potential reputational consequences including operational restrictions by sectoral authorities.
Per Czech Republic - National AI Strategy (2019)
- The 2019 NAIS is a strategic, non-binding framework and does not itself establish new administrative fines or criminal penalties.
- Enforcement for data protection violations continues to be under the Office for Personal Data Protection (Úřad pro ochranu osobních údajů) and GDPR sanctions apply where relevant.
- Sectoral safety or consumer protection breaches are subject to existing Czech civil, administrative or criminal law as applicable.
- NAIS recommends legal reviews to specify liability or sanctions for particular high-risk AI applications; such penalties would be introduced through primary legislation or sectoral regulation.
Czech Republic overview
The full picture of AI regulation in Czech Republic, beyond just the EU AI Act.
Czech Republic AI regulation overview →